At ThunderPanel, we are committed to protecting your privacy and maintaining the security of your data.
This policy explains how we collect, use, and safeguard your information when you use our server monitoring platform.
1. Information We Collect
1.1 Account Information
When you create an account with ThunderPanel, we collect:
Identity Information: Name, email address, and profile information from OAuth providers (Discord, Google)
Authentication Data: OAuth tokens and session information for secure access
Account Preferences: Dashboard settings, notification preferences, and customization options
1.2 Server Monitoring Data
To provide our monitoring services, we collect:
Server Metrics: CPU usage, memory consumption, disk space, network statistics
Performance Data: Response times, uptime/downtime records, system health indicators
Configuration Information: Server hostnames, IP addresses, service configurations
Log Data: System logs, error messages, and diagnostic information (when enabled)
Hardware Information: Server specifications, firmware versions, hardware health status
1.3 Usage Information
We automatically collect information about how you use our service:
Application Usage: Pages visited, features used, time spent in the application
Technical Information: Browser type, operating system, IP address, device information
API Usage: API endpoints accessed, request frequency, authentication methods
2. How We Use Your Information
2.1 Service Provision
We use your information to:
Monitor your servers and provide real-time alerts
Generate performance reports and analytics
Maintain service availability and troubleshoot issues
Provide customer support and technical assistance
2.2 Service Improvement
We analyze usage patterns to:
Improve our monitoring algorithms and detection capabilities
Enhance user interface and user experience
Develop new features and functionality
Optimize system performance and reliability
2.3 Communication
We may use your contact information to:
Send service notifications and alerts
Provide important updates about our service
Respond to your inquiries and support requests
Send occasional product updates and feature announcements (with your consent)
3. Data Sharing and Disclosure
3.1 We Do Not Sell Your Data
ThunderPanel does not sell, rent, or trade your personal information or server data to third parties for monetary consideration.
3.2 Limited Sharing
We may share your information only in the following circumstances:
Service Providers: With trusted third-party vendors who help us operate our service (hosting, analytics, support tools)
Legal Compliance: When required by law, court order, or government request
Business Transfer: In connection with a merger, acquisition, or sale of assets (with user notification)
Security Protection: To protect the rights, property, or safety of ThunderPanel, our users, or others
3.3 Data Processing Partners
Partner
Purpose
Data Type
Location
Cloud Infrastructure Provider
Service hosting and data storage
All user data
US/EU
Authentication Services
OAuth authentication
Identity information
Global
Analytics Service
Usage analytics (anonymized)
Usage patterns
US
4. Data Security
4.1 Security Measures
We implement comprehensive security measures including:
Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
Access Controls: Role-based access controls and multi-factor authentication
Infrastructure Security: Regular security audits, vulnerability scanning, and penetration testing
Data Isolation: Customer data is logically separated and cannot be accessed by other customers
Monitoring: 24/7 security monitoring and incident response procedures
4.2 Data Backup and Recovery
We maintain regular encrypted backups of your data and have established disaster recovery procedures
to ensure business continuity and data availability.
5. Data Retention
5.1 Retention Periods
We retain different types of data for varying periods:
Account Information: Until account deletion or 2 years after last activity
Server Monitoring Data: Based on your subscription plan (typically 30 days to 2 years)
Log Data: 90 days for security and troubleshooting purposes
Billing Information: 7 years for tax and legal compliance
5.2 Data Deletion
When data is deleted, it is permanently removed from our active systems within 30 days.
Backup copies are deleted within 90 days unless longer retention is required by law.
6. Your Privacy Rights
6.1 Access and Control
You have the right to:
Access: Request a copy of your personal information
Correction: Update or correct inaccurate information
Deletion: Request deletion of your personal information
Portability: Export your data in a common format
Restriction: Limit how we process your information
6.2 Exercising Your Rights
To exercise these rights, contact us at privacy@thunderpanel.com.
We will respond within 30 days and may require identity verification.
6.3 Data Subject Rights (GDPR)
If you are in the European Economic Area, you have additional rights under GDPR, including the right to
object to processing and the right to lodge a complaint with your local data protection authority.
7. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence.
We ensure appropriate safeguards are in place for international transfers, including:
Standard Contractual Clauses approved by the European Commission
Adequacy decisions where applicable
Additional security measures for data protection
8. Cookies and Tracking
8.1 Cookies We Use
We use cookies and similar technologies for:
Essential Cookies: Required for service functionality (authentication, session management)
Analytics Cookies: To understand usage patterns and improve our service
Preference Cookies: To remember your settings and preferences
8.2 Cookie Management
You can control cookies through your browser settings. Note that disabling essential cookies may affect
service functionality.
9. Third-Party Integrations
Our service may integrate with third-party services (OAuth providers, notification services).
These integrations are governed by the privacy policies of those third parties:
Our service is not intended for children under 13 years of age. We do not knowingly collect personal
information from children under 13. If we learn that we have collected such information, we will
delete it immediately.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Sending an email notification to your registered email address
Posting a notice in our application
Updating the "Last Updated" date at the top of this policy
Your continued use of our service after such modifications constitutes acceptance of the updated Privacy Policy.
12. Contact Information
If you have any questions about this Privacy Policy or our privacy practices, please contact us: